This article describes how to set up a FortiAnalyzer playbook that automatically bans a source IP address whenever traffic matches a block policy in FortiGate. By using automation stitches, the system can quickly identify and respond to threats in real-time, improving network security.
The guide provides a detailed, step-by-step process for configuring FortiAnalyzer playbooks, integrating them with FortiGate automation stitches, and verifying the IP banning procedure.
FortiGate, FortiAnalyzer.
Go to -> FortiSoc -> Handlers -> Even Handler List -> Create New, select the data selector created in the above step and create a new rule.
After the Event trigger is chosen, the next step is FOS_WEBHOOK.
Creating the Report:
The report will be available under the playbook once Enable Auto-cache and extended log filtering are enabled on report settings
The Playbook monitor shows a successful:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.